CVE-2024-9675
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache dir
CVSS
7.8
Alto
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Publicado: 9 oct 2024 · Última mod.: 7 ago 2026 · CWE-22
0.4%EPSS · 30 días0.4%
2026-08-242026-09-22
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
- access.redhat.comhttps://access.redhat.com/errata/RHBA-2024:10967
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8563
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8675
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8679
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8686
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8690
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8700
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8703
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8707
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8708
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8709
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8846
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8984
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:8994
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:9051
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:9454
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2024:9459
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:2445
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:2449
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:2454
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-772696.5 MED—
——0MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not constrain source paths used by attachment uploads. A caller can provide an absolute or traversal file_path and cause the server to upload the selected local file. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.1hCVE-2026-772666.5 MED—
——0MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server workspace. An MCP caller with attachment access can read a chosen server-local file and exfiltrate it through Jira or Confluence. The advisory traces the vulnerable input and processing flow through upload_attachment, file_path, and path traversal, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.1hCVE-2026-772628.6 ALT—
——0MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does not apply the path restriction added for the earlier download vulnerability. A caller can traverse outside the workspace and upload arbitrary server-readable files to Confluence. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, file_path, and CVE-2026-27825, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.1hCVE-2026-772597.7 ALT—
——0MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains in the workspace. A caller can upload environment files, credentials, or other readable host data to a Confluence page and retrieve it through Atlassian. The advisory traces the vulnerable input and processing flow through confluence_upload_attachment, file_path, and open(file_path, "rb"), which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.1hCVE-2026-77257——
——0MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to local file operations without restricting it to the workspace. A remote MCP caller with tool access can cause the server to read sensitive local files and upload them as Atlassian attachments. The advisory traces the vulnerable input and processing flow through streamable-http, upload_attachment, and file_path, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.1hCVE-2026-772558.6 ALT—
——0MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementation without workspace validation. A caller can make the MCP server read arbitrary local files and attach them to a Jira issue, using the server as a confused deputy to exfiltrate the contents. The advisory traces the vulnerable input and processing flow through jira update_issue, attachments, upload_attachment, and file_path, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.1h